Privacy Policy
Last updated: March 19, 2026
Cookie Settings
Manage your cookie preferences
Contents
1. Who We Are
Quality QR is a QR code generation and analytics platform operated by:
Silly Geese Solutions / Silly Geese OÜ
Registry code: 16121252
Registered: 15.12.2020
VAT: EE102322819
Country: Estonia, European Union
General Contact: cs@quality-qr.app
GDPR / CCPA Inquiries: gdpr@quality-qr.app
2. Data We Collect
2.1 Account Data
When you create an account, we collect:
- Email address (required for account creation and communication)
- Name (optional, for personalization)
- Avatar selection (optional)
- Authentication credentials (securely hashed, never stored in plain text)
2.2 Payment Data
For paid subscriptions, payment processing is handled by Stripe. We store only:
- Stripe customer ID (reference only)
- Subscription status and plan type
We never store your full credit card number, CVV, or other payment card details.
2.3 QR Code Scan Analytics
When someone scans your dynamic QR code, we collect:
- Hashed IP address — SHA-256 hashed for unique visitor counting
- Geolocation — Country, city, region from Cloudflare headers
- Device information — Device type, browser, OS
- User agent string — Browser identification
- Referrer URL — Source page (if available)
- Timestamp — When the scan occurred
Privacy Note
We do not store raw IP addresses. All IP addresses are cryptographically hashed before storage.
2.4 Feature-Specific Data
Depending on features you use, we may collect:
- QR code content and destination URLs — The URLs and content you configure in your QR codes, which may be reviewed by our team for compliance with our acceptable use policy
- A/B Test data — Test configurations, variant URLs, traffic distribution, and performance metrics
- Bundle/Campaign data — Campaign names, associated QR codes, and aggregated analytics
- Alert configurations — Threshold settings, notification preferences, and trigger history
- Version history — QR code configuration changes and timestamps for rollback capability
- Design templates — Saved QR code design configurations (colors, patterns, logos) for reuse
- Team collaboration data — Team membership, roles, invitations, and audit logs of team actions
3. How We Use Your Data
We use your data for:
- Providing QR code generation and tracking services
- Displaying scan analytics in your dashboard
- Processing payments and managing subscriptions
- Sending essential account notifications
- Improving our services through aggregated analytics
- Measuring advertising performance and showing relevant ads (with your consent)
- Sending lifecycle and promotional emails (with opt-out)
- Preventing fraud and abuse, including reviewing QR code destination URLs to ensure compliance with our acceptable use policy
- Complying with legal obligations
Legal Basis for Processing (GDPR & CCPA)
- Contract: Processing necessary to provide our services
- Legitimate Interest: Analytics and service improvements
- Consent: Marketing cookies, remarketing, and promotional emails
- Legal Obligation: Compliance with laws
4. Advertising and Remarketing
We use Google Ads to promote Quality QR. When you consent to marketing cookies, we may use the following features:
4.1 Google Ads Conversion Tracking
When you arrive at Quality QR through a Google ad, a conversion tracking cookie may be placed on your device. This helps us measure the effectiveness of our advertising campaigns. The cookie expires after 30 days and does not contain personally identifiable information.
4.2 Remarketing
With your consent, we may use Google Ads remarketing to show you relevant ads on other websites after you visit Quality QR. This uses cookies to identify your browser (not you personally) and display ads based on your visit.
4.3 European User Consent (EEA/UK)
In compliance with Google's EU User Consent Policy, we obtain your explicit consent before:
- Placing marketing or advertising cookies on your device
- Using personal data for personalized advertising (remarketing)
- Using cookies to track conversions from ad clicks
You can withdraw your consent at any time via our cookie settings or through Google's Ad Settings.
No Tracking Without Consent
Marketing cookies are disabled by default. Google Ads tracking only activates after you explicitly accept marketing cookies through our cookie banner.
5. Email Communications
5.1 Transactional Emails
We send emails necessary for your account, including password resets, security alerts, and payment confirmations. These cannot be opted out of as they are required for the service.
5.2 Lifecycle Emails
After you sign up, we may send a small number of onboarding and engagement emails to help you get started with Quality QR. These are limited in scope and frequency.
5.3 Opting Out
Every lifecycle email includes a one-click unsubscribe link. Once you unsubscribe, you will not receive any further marketing or lifecycle emails. You can also contact gdpr@quality-qr.app to opt out.
6. Third-Party Data Processors
We work with trusted third-party providers:
Google LLC
Analytics (Google Analytics) and advertising (Google Ads conversion tracking and remarketing). Only activated with your consent.
Google Privacy Policy →7. Data Retention
We retain your data for:
| Data Type | Retention Period |
|---|---|
| Account data | Until account deletion |
| QR code data | Until QR/account deletion |
| Scan analytics | 2 years |
| A/B test data | Until test/account deletion |
| Bundle/Campaign data | Until bundle/account deletion |
| Design templates | Until template/account deletion |
| Version history | Per plan limits (30-90 days) |
| Team audit logs | 1 year |
| Cookie consent | 2 years |
| Email send history | Until account deletion |
| Support tickets | Resolved + 1 year |
8. Your Rights (GDPR & CCPA)
Under GDPR and CCPA, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Request deletion ("right to be forgotten")
- Portability: Receive data in machine-readable format
- Restriction: Limit processing of your data
- Object: Object to legitimate interest processing
- Withdraw Consent: Withdraw consent anytime
- Do Not Sell (CCPA): We do not sell personal information. California residents can confirm this at any time.
- Non-Discrimination (CCPA): Exercising your privacy rights will not affect service quality or pricing
Exercise these rights via account settings or contact gdpr@quality-qr.app
10. Data Security
We protect your data with:
- Encryption in transit (TLS/HTTPS)
- Encryption at rest for sensitive data
- Password hashing using industry-standard algorithms
- IP address hashing (SHA-256 with salt)
- Access controls and authentication
- Regular security assessments
11. International Data Transfers
Our primary processing occurs in the EU. For transfers outside the EU, we use:
- EU Standard Contractual Clauses
- Adequacy decisions by the European Commission
- Binding Corporate Rules (where applicable)
12. Changes to This Policy
We will notify you of changes by:
- Posting the updated policy on this page
- Updating the "Last updated" date
- Email notification for material changes
13. Contact Us
Questions about this policy? Contact us:
Email: gdpr@quality-qr.app
We respond within 30 days.
Supervisory Authority
You may lodge a complaint with the Estonian Data Protection Inspectorate: